4.7 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
4 packages
- mattermost
- mattermostLatest
- python313Packages.mattermostdriver
- python314Packages.mattermostdriver
- @LeSuisse accepted
- @LeSuisse published on GitHub
Mattermost Desktop local network access from server-rendered content
Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement under the Mattermost responsible disclosure policy. Mattermost Advisory ID: MMSA-2026-00698
References
-
MMSA-2026-00698 vendor-advisory
Affected products
- =<6.2.2
- ==6.2.3.0
- ==6.3.0
Matching in nixpkgs
Ignored packages (4)
pkgs.mattermost
Open source platform for secure collaboration across the entire software development lifecycle
pkgs.mattermostLatest
Open source platform for secure collaboration across the entire software development lifecycle
pkgs.python313Packages.mattermostdriver
Python Mattermost Driver
Package maintainers
-
@jokogr Ioannis Koutras <ioannis.koutras@gmail.com>
-
@liff Olli Helenius <liff@iki.fi>
-
@yayayayaka Yaya <github@uwu.is>
3.7 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): Low (L)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
4 packages
- mattermostLatest
- mattermost
- python313Packages.mattermostdriver
- python314Packages.mattermostdriver
- @LeSuisse accepted
- @LeSuisse published on GitHub
Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler
Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging to a different connected server via the desktopAPI.leaveCall IPC message. Mattermost Advisory ID: MMSA-2026-00699
References
-
MMSA-2026-00699 vendor-advisory
Affected products
- =<6.2.2
- ==6.2.3.0
- ==6.3.0
Matching in nixpkgs
Ignored packages (4)
pkgs.mattermost
Open source platform for secure collaboration across the entire software development lifecycle
pkgs.mattermostLatest
Open source platform for secure collaboration across the entire software development lifecycle
pkgs.python313Packages.mattermostdriver
Python Mattermost Driver
Package maintainers
-
@liff Olli Helenius <liff@iki.fi>
-
@yayayayaka Yaya <github@uwu.is>
-
@jokogr Ioannis Koutras <ioannis.koutras@gmail.com>
2.6 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
4 packages
- mattermost
- mattermostLatest
- python313Packages.mattermostdriver
- python314Packages.mattermostdriver
- @LeSuisse accepted
- @LeSuisse published on GitHub
Mattermost Desktop App plugin popout scheme validation bypass
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. Mattermost Advisory ID: MMSA-2026-00717
References
-
MMSA-2026-00717 vendor-advisory
Affected products
- =<6.2.2
- ==6.2.3.0
- ==6.3.0
Matching in nixpkgs
Ignored packages (4)
pkgs.mattermost
Open source platform for secure collaboration across the entire software development lifecycle
pkgs.mattermostLatest
Open source platform for secure collaboration across the entire software development lifecycle
pkgs.python313Packages.mattermostdriver
Python Mattermost Driver
Package maintainers
-
@liff Olli Helenius <liff@iki.fi>
-
@yayayayaka Yaya <github@uwu.is>
-
@jokogr Ioannis Koutras <ioannis.koutras@gmail.com>